Test & Evaluation
This section outlines the key components that have been identified for the Test & Evaluation dimension as well as maturity levels within the components. These components and levels form the basis for assessing how threat informed an organization’s T&E program is. This assessment can be conducted using the companion spreadsheet published with this white paper.
Type of Testing
Are cybersecurity tests focused on helping defenders improve against prioritized threats?
Frequency of Testing
Do your tests keep pace with changing adversaries and defended technologies?
None
Annual
Semi-Annual
Monthly
Continuous
Test Planning
Are tests coordinated and prioritized on the most relevant threat behaviors?
None
Ad hoc
Deliberately planned and scoped, informed by Threat Actor or prioritized TTPs 3
Collaboratively planned with Defenders, focused on known gaps and validating coverage
Collaboratively planned with Defenders, linked to organizational Metrics or KPIs
Test Execution
Does testing cover adversary TTPs in addition to traditional IOCs?
Test Results
How effectively do test results cause improvements in defensive measures?
None
Results generated
Results generated, leadership interest, actions taken
Results formally tracked; findings drive detection improvements and architectural changes
Results formally tracked; findings drive organizational programs, hiring, training, and other significant investments
References